Skip to main content

Navigating the Questionnaire

Its not paper. Its not a .pdf. Its an interactive library.

Updated over 2 months ago

1. From the Home page, navigate to The Cyber Questionnaire Validator.

2.

Select an entity to review their assessment results and questionnaire progress.

This entity has 10 questions ready to review.

3. The status field indicates that some questions have been answered.

4. The Hacker Threat Analysis is also complete.

5. The BreachRisk™ a.i. Analysis Status shows that partial results are available for review.

6. It appears that 10 verified answers are ready for review.

7. The pie chart indicates that we'll find 1 question that's judged to be "unfavorable" from the hacker's perspective.

8. And the pie chart also indicates that the vast majority of questions have favorable answers.

9.

Open the Details view by clicking on a question.

Or, select the Details icon on the right side of the row.

10. For this applicant, we're intersted about email security. So let's select the DMARC question and review the evidence collected by BreachRisk™ a.i.

11. Let's also check SPF, since it's related to email.

12. Click Close to return to the main questionnaire after viewing detailed evidence.

13.

Some questions are contextual.

This means that from the hacker's perspective, the answer is merely for context and does not directly contribute to low or high threat.

14.

Some questions can be answered "Yes" or "No" but there is no judgement.

For many businesses, the use of certain technologies is a business decision that is neither "good" nor "bad."

15.

For contextual and non-judgement answers, look to the Answer Context for insights.

For each question, there's also Question Context, which is insights from hackers and security professionals on why this question matters.

16. Use the Copy Text button to quickly transfer assessment details for external documentation or to communicate an indication of interest.

17.

Did you know that hackers also ask themselves questions while they plan attacks?

Some of these questions are not on insurance questionnaires, but we provide them here in The Cyber Questionnaire Validator.

18.

BreachRisk™ a.i. quantifies the risk of a cyber breach based on how easy it is to actually break in - and the damage hackers believe they can do if they succeed.

This is called BreachRisk™ Score. It is standardized across all entities. A lower score means lower threat.

19. The questionnaire should be all that you need to make a fast and confident decision. But if you really want advanced insights, show advanced hacker threat analysis for detailed BreachRisk™ AI findings.

20. You can also toggle Show Advanced Insights to display hacker insights by default.

21.

Review the Hacker's Plan of Attack for risk breakdown by attack vector.

These are the attack pathways that real attackers are planning to use. Some are more dangerous than others...

22. Hackers compare entities and tend to attack those that are easier to attack with higher impact.

23. Hackers care most about attack pathways that are Verified, with evidence that the pathway is not blocked by defenses.

24. Copy the courtesy disclosure statement to efficiently share threat information.

25. Copy a subjectivity statement for underwriters that need to know more, or for brokers conducting insurability assessments.

26.

Your brokers, carriers, and policyholders probably use legacy cyber tools that alert to "false positives."

These items appear to be a threat on casual scans, but BreachRisk™ a.i. is telling you that these threats aren't real! They are blocked or impractical. Use these items as reason proceed with the policy.

27. There are plenty of good reasons to say "Yes" to this applicant.

28.

Are you satisfied with this applicant? If so, move it to your book.

Entities on Your Book are monitored by Cyber Pre-Claim Intervention. So you can write now, and manage later.

29.

If this applicant is not within your risk profile, then decline them.

You'll get periodic updates to inform your performance reviews so everyone will know you made the right decision.


Did this answer your question?